TheVortiq
Inteligencia Artificial

WiFi as a surveillance system: the new threat to privacy

KIT researchers demonstrate how wireless signals can identify people without the need for connected devices.

August 19, 2026 · 4 min read

Black and white photo of a streetlight and security camera against a modern building and sky.

TL;DR: A KIT study reveals that unencrypted WiFi signals can generate images of people and recognize them with near-total accuracy. This technique works even without the individual carrying devices, turning the wireless environment into a constant surveillance tool.

The end of wireless anonymity: When the environment becomes a sensor

Cybersecurity has historically operated under the paradigm that anonymity is preserved by turning off devices or disconnecting from the network. However, disruptive research from the Karlsruhe Institute of Technology (KIT) has shattered this premise. The team led by Professor Thorsten Strufe, from the KASTEL institute, has demonstrated that everyday WiFi signals can be transformed into a visual surveillance tool capable of identifying individuals with nearly 100% accuracy, even if the subject is not carrying any technological device. This finding is not just a technical curiosity; it is a redefinition of what constitutes a 'data leak' in the era of hyperconnectivity.

How does this detection technology work?

The core of the system lies in the exploitation of Beamforming Feedback Information (BFI). In modern WiFi standards (such as 802.11ac or Wi-Fi 6), routers and connected devices constantly exchange data to optimize signal directionality and power, ensuring that the connection is efficient even in environments with obstacles. This communication, necessary for network optimization, is transmitted without any encryption.

The system developed by KIT intercepts these signals passively. By analyzing how radio waves bounce off the human body and the environment, the software is capable of reconstructing a visual representation or 'radio image' of the space. As Professor Strufe points out, the process is analogous to conventional photography, but replacing light photons with radiofrequency electromagnetic waves. Thanks to specifically trained machine learning models, the system can identify a person based on their anatomy and movement patterns in a matter of seconds. In tests conducted with 197 participants, the success rate was virtually total, regardless of the observation angle or the subject's gait cadence.

Impact and privacy risks: A paradigm shift

The ability to identify people without their consent and without the need for them to interact with the network poses unprecedented risks that exceed traditional surveillance tactics. The critical points identified are:

  • Device independence: Unlike geolocation techniques based on tracking MAC addresses or Bluetooth signals, this method does not require the target to carry a phone, tablet, or smartwatch. The presence of other WiFi devices in the vicinity is sufficient for the system to act as a high-resolution radar.
  • Passive and pervasive surveillance: The nature of radio waves allows the system to 'see' through physical obstacles such as furniture or thin walls. This eliminates the traditional refuge of the domestic private space, turning walls into transparent elements for an attacker equipped with the appropriate technology.
  • Systemic vulnerability: The problem is not a specific software bug, but a design decision in network protocols (BFI). Efficiency was prioritized over security, leaving a door open that, until now, was not considered a viable attack vector.

Historical context and comparison with previous events

This breakthrough is the logical evolution of previous research on WiFi-based presence detection, which could previously only determine if a room was occupied. However, the ability for biometric identification through radiofrequency places this finding in a category similar to the revelation of vulnerabilities in the SS7 protocols of mobile networks or side-channel attacks like Spectre and Meltdown. Like the latter, the KIT method demonstrates that the fundamental layers of technology we take for granted—in this case, wireless communication—can be double-edged swords.

Historically, digital privacy focused on protecting the content of messages (end-to-end encryption). This new scenario forces us to protect the physical environment. The analogy is clear: just as we learned to encrypt internet traffic with HTTPS to prevent packet sniffing, the market must now face the challenge of implementing security layers in radiofrequency management signals. It is speculated, although not confirmed by hardware manufacturers, that the next generation of WiFi standards (such as Wi-Fi 7 or 8) could include obfuscation or encryption mechanisms to mitigate this interception.

The future of cybersecurity: Towards an invisible network?

We are at the beginning of an arms race in the radio spectrum. Network infrastructure companies now face an architectural challenge: how to maintain the efficiency of beamforming without exposing user identity? The answer will likely come from differential privacy techniques or the encryption of BFI packets, although this would require a massive global update of the router fleet.

For the average user, the conclusion is unsettling: anonymity in public and private spaces is under constant siege. As machine learning technology becomes more sophisticated and accessible, the 'radioelectric footprint' we leave when walking becomes as identifiable as our fingerprint or our face. Protecting our wireless signals will not just be a matter of network configuration, but the next great battlefront for civil liberties in the digital age. For now, this breakthrough remains in the experimental realm, but its scalability potential suggests that the privacy of the physical environment is a concept we must urgently begin to renegotiate.

Keep reading